filename | Extrato.exe | |
---|---|---|
size | 370176 (0x5a600) | |
md5 | 60811087674a608512a6c66d2992c1e5 | |
type | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed | |
mimetype | application/x-dosexec | |
clamav | OK | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x90 |
blocks_in_file | 3 |
num_relocs | 0 |
header_paragraphs | 4 |
min_extra_paragraphs | 0 |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0x40 |
overlay_number | 0 |
reserved0 | 0 |
oem_id | 0 |
oem_info | 0 |
reserved2 | 0 |
reserved3 | 0 |
reserved4 | 0 |
reserved5 | 0 |
reserved6 | 0 |
lfanew | 0x110 |
Rich Header
lib id | version | times used |
---|---|---|
199 | 41118 | 1 |
205 | 50929 | 51 |
206 | 50929 | 177 |
207 | 50929 | 50 |
131 | 30729 | 9 |
147 | 30729 | 37 |
1 | 0 | 530 |
216 | 61030 | 77 |
205 | 61030 | 2 |
201 | 61030 | 1 |
151 | 0 | 1 |
204 | 61030 | 1 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Packer / Compiler
UPX Modified >> *$igBy Ahmed18 This file is packed with UPX. Analysis will be incomplete without unpacking. |
Sections
name | va | vsize | raw size | flags | |
---|---|---|---|---|---|
UPX0 | 0x1000 | 0x89000 | 0 | RWX UDATA | |
UPX1 | 0x8a000 | 0x55000 | 0x54200 | RWX IDATA | |
.rsrc | 0xdf000 | 0x6000 | 0x6000 | RW- IDATA |
Data Directory
type | va | size | |
---|---|---|---|
EXPORT | 0 | 0 | |
IMPORT | 0xe4bbc | 0x424 | |
RESOURCE | 0xdf000 | 0x5bbc | |
EXCEPTION | 0 | 0 | |
SECURITY | 0 | 0 | |
BASERELOC | 0xe4fe0 | 0x18 | |
DEBUG | 0 | 0 | |
ARCHITECTURE | 0 | 0 | |
GLOBALPTR | 0 | 0 | |
TLS | 0 | 0 | |
LOAD_CONFIG | 0xde1b4 | 0x48 | |
Bound_IAT | 0 | 0 | |
IAT | 0 | 0 | |
Delay_IAT | 0 | 0 | |
CLR_Header | 0 | 0 |
id | lang | string |
---|---|---|
96 | 2057 | cc 20 f2 b8 44 40 1c bf 89 45 7a 3a 54 50 02 84 |. ..D@...Ez:TP..| 0c 06 1c 1e 44 38 42 ec e7 90 90 86 e8 58 54 46 |....D8B......XTF| 36 0e b6 81 4e cf f8 97 00 0e 22 84 23 62 70 d8 |6...N.....".#bp.| e1 93 84 cc e5 b8 1a 85 c7 db 01 42 dd 67 00 1b |...........B.g..| f7 02 ec b8 19 2b 93 84 1a 7e 02 39 e1 5a a9 f9 |.....+...~.9.Z..| 12 70 1b 3c e0 e6 d4 55 45 28 f7 40 50 65 30 8d |.p.<...UE(.@Pe0.| 0d 19 69 1d 40 75 03 35 4e ba e4 37 e6 8d 95 47 |..i.@u.5N..7...G| 6c a4 85 f0 63 f7 76 5e 5d 23 81 ce 7a 62 12 31 |l...c.v^]#..zb.1| 3a c6 12 40 91 45 06 ee f6 21 b0 63 26 01 6d 1a |:..@.E...!.c&.m.| f7 41 b7 7c 0f 60 ee 75 63 ea e9 76 98 05 97 40 |.A.|.`.uc..v...@| 08 91 17 75 45 cc 45 fb f1 aa 05 4d 9c 7b 90 16 |...uE.E....M.{..| 94 83 a9 b4 d8 d0 1f af 2c 70 46 1b b4 9a b8 a1 |........,pF.....| a5 23 5e 1c 81 e3 b1 e3 b5 05 61 b1 37 ed 6b 53 |.#^.......a.7.kS| c0 3f 64 2b f2 d1 fe 01 31 e6 bb 10 21 9c bc bf |.?d+....1...!...| 33 48 4f a7 bd 73 83 fb 5c 8e 66 b7 60 d3 3d 50 |3HO..s..\.f.`.=P| 1c a5 e4 a2 cb 6c 69 40 f8 89 5d 03 37 fe 3a 4e |.....li@..].7.:N| 6b 6e 02 de 08 2e 74 09 3d 54 30 65 c1 3c 1a 25 |kn....t.=T0e.<.%| 2e 6b ad da 6d 74 c2 98 c7 58 08 64 50 16 ee 4b |.k..mt...X.dP..K| 03 8f 14 26 04 5e 75 13 e7 cf 20 04 0f 85 a4 c8 |...&.^u... .....| cf 46 06 70 2c 50 60 95 9e 3d 48 08 28 9d 2b 8b |.F.p,P`..=H.(.+.| d0 84 f0 59 b6 ca c4 24 d8 50 9d 51 49 74 0b 58 |...Y...$.P.QIt.X| c4 df c0 3f fa 9e c1 49 23 d1 60 20 74 30 14 fd |...?...I#.` t0..| c0 93 c4 ac 0e 03 2e 3c f4 14 a1 67 40 88 39 85 |.......<...g@.9.| 5f 30 10 1c 29 c8 91 02 80 5b fa 0d 4e 22 db fd |_0..)....[..N"..| 8d 34 52 6a 20 3e 60 68 4f ff 4c 30 c8 85 2f a7 |.4Rj >`hO.L0../.| 74 b2 44 19 2b 3f 75 2e 03 fe 0d 38 9f 78 2d 07 |t.D.+?u....8.x-.| 20 d5 44 4e 62 18 92 8a 5a 72 a3 fb 04 16 08 84 | .DNb...Zr......| 15 5b 42 56 02 91 70 6a 6e 23 5c c6 00 80 6b 27 |.[BV..pjn#\...k'| ee 27 7e bf b2 a0 d9 c8 09 80 a5 cd 2c c3 eb 0c |.'~.........,...| 50 c1 d3 dc 1a 02 75 07 d7 7f 8a 98 cd dc 3b 18 |P.....u.......;.| f7 18 8a 84 0d 6b 7c a4 0d d8 76 b3 83 3c 52 41 |.....k|...v.. |
112 | 2057 | b0 34 a6 b6 98 4c 42 68 1f 5c 41 fe 56 c4 a1 10 |.4...LBh.\A.V...| 21 4c 87 4d 85 60 42 45 b8 dc ff 06 c6 9b dd c8 |!L.M.`BE........| 07 9a 60 17 11 08 8e 7c 8d 57 1a 6c 60 58 04 aa |..`....|.W.l`X..| bc 85 8a 01 6a 51 e7 15 3d b1 be 7f f5 f6 b6 a5 |....jQ..=.......| bd f7 78 09 b6 50 2e fe 5c 75 34 6b d0 64 69 b9 |..x..P..\u4k.di.| 9b 75 45 7c f6 3c 4f 61 0e 9e 06 cb 63 91 08 41 |.uE|. |
128 | 2057 | 8f 39 16 a8 e1 45 1f b8 03 58 ab 0f 7f 57 01 4a |.9...E...X...W.J| 07 dc 3c b6 3e 12 2f 81 fa 0e 08 fe 1a 1f 90 85 |..<.>./.........| 35 0f 87 27 5e 36 aa 7d 2d ec 00 6e 0d 3f 85 a0 |5..'^6.}-..n.?..| 4f d8 47 40 c7 ba b7 37 e1 5e 90 54 22 0f 8f 94 |O.G@...7.^.T"...| 28 42 3c d6 b7 6e ac 8d 56 c8 21 d3 fd c6 27 5c |(B<..n..V.!...'\| eb c7 ca 0f 27 5f ab 8e ba 7d 5a 0e 88 80 b9 0d |....'_...}Z.....| 85 b5 69 41 4e 2e 97 10 14 f4 14 84 16 98 92 10 |..iAN...........| e0 7b f8 2d 81 96 16 a3 10 0e 0d 9f cb 47 71 f4 |.{.-.........Gq.| 14 95 c1 70 0f ce 00 0a 4a 1c 79 26 26 8d e4 e1 |...p....J.y&&...| 8b dd 8f 06 50 10 de 11 8f 15 16 3c 21 34 41 17 |....P.......([...Lc...&..s| 44 73 45 24 c8 0d 81 d3 1b 2f 01 02 90 f8 93 30 |DsE$...../.....0| 51 d8 67 5a 9d b6 ca 10 7e 34 ca fa 37 07 0a d7 |Q.gZ....~4..7...| 72 7b 3f e8 b9 6d 1a e0 8b e8 3e 14 16 74 0a 77 |r{?..m....>..t.w| 22 61 49 76 38 8a da 92 7e 08 a2 13 99 07 bb c3 |"aIv8...~.......| e9 8b 49 6a c3 b6 df 2b da d1 fb d4 9c 18 fb ec |..Ij...+........| 3a 75 4a 3d 60 a2 66 ec 02 d6 26 21 4c 0e 31 bd |:uJ=`.f...&!L.1.| 40 81 6e 26 2e f7 c8 81 fe 09 79 44 2e f5 a6 4b |@.n&......yD...K| db d2 82 7e 9e 29 75 4c 8d 3e 68 96 a6 75 a4 09 |...~.)uL.>h..u..| fc 16 04 80 7f 84 b8 3b da 75 19 6b 30 6e 12 c2 |.......;.u.k0n..| b0 53 79 24 c2 c4 20 da 42 b3 87 24 6d cb e0 40 |.Sy$.. .B..$m..@| 0a 3c 5a 7e dd 03 22 22 14 6f 3d 84 d4 7c c1 b2 |. |
144 | 2057 | 1f 57 04 28 45 3a a4 00 ad 6e c4 8b 0d 46 9a 5a |.W.(E:...n...F.Z| 77 ea 8f 6e d6 a7 e0 7d 9e 09 43 cd 09 99 a9 41 |w..n...}..C....A| 4c 01 2b 46 d3 be 77 c5 57 56 21 18 e9 9c 1d 9b |L.+F..w.WV!.....| 4f 55 77 b5 15 51 16 d0 4b 7d 78 13 27 59 4e 2f |OUw..Q..K}x.'YN/| 71 2f d4 03 0e c7 ed 21 74 50 08 3d 74 32 61 77 |q/.....!tP.=t2aw| 10 2e ea 83 f8 c0 43 a0 10 53 1e 1a b0 d3 fe 09 |......C..S......| 00 18 b9 28 be 79 96 14 7c 86 28 40 4c 26 04 51 |...(.y..|.(@L&.Q| 70 00 e9 31 7a be 7b 7f 61 d3 a5 e0 b8 70 67 30 |p..1z.{.a....pg0| 07 0e 65 08 22 ea c5 70 2e 8d bc b1 d9 20 1a 5d |..e."..p..... .]| bb d1 89 56 50 e4 56 1c 48 5c 65 eb 53 f4 3e 73 |...VP.V.H\e.S.>s| e0 5a 3f 14 09 21 bd 78 88 77 8f f3 08 09 02 04 |.Z?..!.x.w......| 56 45 6f 1d 28 2b 41 18 ee 40 c3 7a c1 3c 1f 1c |VEo.(+A..@.z.<..| a5 47 08 89 da f7 6b ec 3f fb bb ba ef 3e 10 9d |.G....k.?....>..| bc 1e ae 5d 3c b4 ce 9c 32 b9 13 46 73 32 c6 57 |...]<...2..Fs2.W| d7 14 a8 81 ec 84 55 25 91 30 10 b4 26 9e 7e 5d |......U%.0..&.~]| a8 d1 fb 99 f7 66 7c b5 4e 73 96 ac a1 cc 81 7e |.....f|.Ns.....~| 2c 10 27 ee 36 74 1e 6a 8d 7c 52 3b 46 30 90 90 |,.'.6t.j.|R;F0..| 7d 00 4f 89 10 a4 05 4e 53 30 16 6a 11 30 31 22 |}.O....NS0.j.01"| 0b 27 b8 29 9f c1 92 61 2b b5 27 00 76 73 0d 34 |.'.)...a+.'.vs.4| e0 83 fe 4a 3b 74 27 d7 0e 1c 3e 2a 18 21 32 b8 |...J;t'...>*.!2.| 71 28 1a a0 ae dd 85 c2 39 41 2c d2 96 c1 f8 4c |q(......9A,....L| a2 30 b6 7e f2 69 14 a0 11 2c d7 ca 08 f8 82 3f |.0.~.i...,.....?| 66 44 5e 02 75 4b 77 d3 96 8e 44 b2 41 0d 62 29 |fD^.uKw...D.A.b)| e0 ba f7 7c c1 e1 0d cb 20 b0 ae 46 80 06 58 48 |...|.... ..F..XH| 2b a4 ff ca d5 47 51 78 11 b2 47 34 46 3b 79 2c |+....GQx..G4F;y,| 7d 23 eb a1 8b 00 bd 97 95 ee 2c 2b c7 26 82 24 |}#........,+.&.$| 14 02 de f2 e0 52 f8 c6 4e 56 bb 45 41 81 dd 53 |.....R..NV.EA..S| 40 f2 41 b0 6e 58 d2 4d 07 77 aa ab 51 78 31 b8 |@.A.nX.M.w..Qx1.| 14 8b 49 06 00 e1 ae dc 80 41 ae 84 6e 07 eb 01 |..I......A..n...| 4a ba 76 40 0f 75 7c 42 55 b0 d4 60 f0 b1 0a 9b |J.v@.u|BU..`....| 3b 7c cf a4 38 66 02 06 34 c1 60 60 b5 ac bb cd |;|..8f..4.``....| 43 70 03 8f 2d b6 cd 78 74 f1 08 42 2c 83 47 e0 |Cp..-..xt..B,.G.| 53 f1 70 78 9d 8e cb fb 0f 8f 06 37 27 c8 ce 77 |S.px.......7'..w| 25 8f 70 00 ec 8c 9c 90 c1 0f b8 c8 82 5c a6 b4 |%.p..........\..| 00 ea fe fc c4 b3 3c 07 94 5c 40 c9 06 09 81 6b |......<..\@....k| 7a 15 07 96 10 80 34 40 6f 15 72 14 53 28 8b 70 |z.....4@o.r.S(.p| 23 00 5e 09 f6 c8 89 78 1c 03 10 03 1c 0b 81 96 |#.^....x........| 4f 92 f4 d2 76 18 26 77 3b 39 c9 ba 1c 92 19 76 |O...v.&w;9.....v| 1e 1c b6 f7 0d ec 4c 82 33 8c 70 28 b4 54 63 88 |......L.3.p(.Tc.| 58 ba 6d 5d 01 2e 0b aa f6 c8 ce 3c 8c 54 8c d7 |X.m].......<.T..| a4 0c 05 cc eb 09 9c f2 54 3a 45 40 1c be 74 40 |........T:E@..t@| 21 7c d0 d4 fc bc 0b 66 e3 c0 18 04 7d 52 82 0e |!|.....f....}R..| 68 61 5f 29 c3 c8 25 e0 05 16 8c 1f fe 2c 05 fa |ha_)..%......,..| 02 21 1c 7d f5 20 43 18 1a 4c 43 b6 58 c8 6f 2b |.!.}. C..LC.X.o+| b2 c6 62 60 45 a8 6b a9 6f bc a4 d8 a0 d2 6d f1 |..b`E.k.o.....m.| e1 e3 6a 3c 70 fe 67 20 7d 02 b2 f5 0d 36 82 47 |..j |
160 | 2057 | 09 14 0a 14 0b 0c 14 0d 14 0e 14 0f 10 23 17 db |.............#..| fe 14 11 14 12 14 13 90 7e 12 c8 07 b9 16 66 b3 |........~.....f.| d9 bc b0 0e f1 1a 14 18 d9 13 4d 9e cd 7b cf 1b |..........M..{..| da 3a 36 e9 06 9a 17 5d 70 10 1a cf 7b f9 36 d4 |.:6....]p...{.6.| 33 40 d8 b9 1d 7e c0 01 0e 0e 0c 08 05 0e 05 01 |3@...~..........| 7e c9 f7 f0 06 0e 24 0e 00 0a 0e 0b 0e 0c 0e cd |~.....$.........| db 86 40 0d c6 1d e8 06 f3 1e 88 e7 79 9e 20 2b |..@.........y. +| 08 10 18 8a 09 44 98 8c a0 01 06 90 36 ed 01 15 |.....D......6...| 02 44 03 04 b4 04 5c f9 0b 05 06 6a 76 4f 1b 70 |.D....\....jvO.p| e4 7d 20 aa 00 42 6c 5a e7 eb 23 43 de 1d 03 53 |.} ..BlZ..#C...S| e6 be 34 85 42 f2 40 26 c1 ea 0b 52 ff 91 92 e2 |..4.B.@&...R....| 43 51 23 d3 8b c8 19 7a 50 22 71 8c fd f1 66 03 |CQ#....zP"q...f.| 76 b6 5f 64 52 54 82 14 3b 4f 40 ef bd 60 0d 58 |v._dRT..;O@..`.X| a6 a0 08 2f 06 74 4c 58 64 05 5d 2e 80 05 8a eb |.../.tLXd.].....| 0f 22 fc 2d 48 30 27 74 10 19 63 08 b3 f0 d1 6b |.".-H0't..c....k| 35 01 2d 55 33 3c 80 81 84 4e c1 a2 25 08 d8 4d |5.-U3<...N..%..M| d9 4c 76 78 b6 10 a4 c1 7b 5c 58 3e 0e e1 4f 7d |.Lvx....{\X>..O}| 22 5c d1 80 6a 72 59 3c 07 47 8a ba 04 1e 78 7e |"\..jrY<.G....x~| 08 a9 4d 9d 53 8e 8d 74 3d 6e 58 b8 a2 2f 42 66 |..M.S..t=nX../Bf| 2d 95 8d c5 e6 65 1a e3 0d be f3 2b 0f 85 93 4c |-....e.....+...L| 6a a5 dc 0f 88 25 c1 05 90 e6 c5 a5 5e 2c 04 02 |j....%......^,..| eb 55 3d 70 7e ae 4f 34 bc 04 43 46 65 a0 3e 04 |.U=p~.O4..CFe.>.| 75 5a a6 55 fc 8d dc 60 49 56 4b a6 00 6a 0b 68 |uZ.U...`IVK..j.h| dc 1d eb e0 47 3a 7c 42 a7 fd 25 f8 f1 eb 18 3b |....G:|B..%....;| f8 ba 35 9d ee 21 14 1a 06 82 1f 25 49 2a bd 49 |..5..!.....%I*.I| fc ac 6b 90 d0 49 fe 71 f8 44 20 b3 00 0d 05 82 |..k..I.q.D .....| 20 d6 8c a6 3a fb 83 f7 f8 84 06 73 43 11 03 88 | ...:......sC...| 70 0f 36 c4 60 d6 0a 87 77 6f ee 43 a0 0a 33 94 |p.6.`...wo.C..3.| 63 b8 f9 ff 3a 35 6e 2b a5 a9 11 dc ba 73 a4 7d |c...:5n+.....s.}| 28 48 48 0e 8f 85 3e 43 53 5b 3f c3 10 6a 1b 3d |(HH...>CS[?..j.=| 86 ce 6e 11 3a a3 90 c2 3d 8b 15 8f 85 ee 88 ba |..n.:...=.......| 32 08 78 ac 78 18 0c fc 85 a4 5f 83 39 71 74 f3 |2.x.x....._.9qt.| 73 e8 10 4f 38 39 52 0d b4 3e 08 f7 9e a9 f4 47 |s..O89R..>.....G| b0 08 16 e8 be bd 41 8b ff 41 10 57 60 4f 27 c6 |......A..A.W`O'.| d8 0d 43 93 61 61 18 9a 80 e2 08 0b 4e c2 93 6d |..C.aa......N..m| 9c dc 4f 62 f8 0a 40 1b 84 cc 41 09 09 f7 a2 ee |..Ob..@...A.....| 04 20 6e 86 62 b0 2d 24 e6 28 3e 70 f2 82 c7 6a |. n.b.-$.(>p...j| 90 82 ba 3d 9a 7c 0b 5d cc 9a 94 79 8e 40 43 c7 |...=.|.]...y.@C.| a1 d4 a4 6e e4 69 2e 29 2c d2 60 70 d5 a4 61 8d |...n.i.),.`p..a.| 13 1e 8c 41 86 f3 8c 69 61 39 f8 14 54 0c 74 fb |...A...ia9..T.t.| 85 5f 86 f2 a0 db 93 c4 2b 8f e8 13 7f a1 dd a0 |._......+.......| 13 ac 4d d5 6f d3 eb 02 c9 37 1c 9a b8 c4 46 08 |..M.o....7....F.| 71 45 58 2c 68 28 10 1f 01 7a 0d 42 b7 0d e1 83 |qEX,h(...z.B....| 69 dd 6a 4a b1 4c c0 42 a2 90 b4 81 cf 09 e5 72 |i.jJ.L.B.......r| f2 ec 52 b1 1b 00 00 20 0f 04 35 40 18 8d b8 3b |..R.... ..5@...;| c2 1e 50 91 9a 0e 8b 04 43 1c d0 51 09 53 36 d0 |..P.....C..Q.S6.| bd ff c0 a4 96 fe 98 99 99 19 77 1c 38 7b 7b 69 |..........w.8{{i| 18 45 2a b0 f0 47 19 53 17 c6 98 53 2e f0 30 1e |.E*..G.S...S..0.| e3 55 24 89 5e 7d 9a 6a 29 52 07 80 dd 14 14 4b |.U$.^}.j)R.....K| ec 2a a3 07 52 1e 17 12 83 99 6d 56 06 70 81 4d |.*..R.....mV.p.M| a4 07 1e eb 75 90 01 42 a6 f5 12 7f 74 78 a5 7b |....u..B....tx.{| e4 73 0a ed 40 e4 8d 71 01 0b b7 5e 63 08 da 05 |.s..@..q...^c...| b8 0f 08 13 8e a7 49 0d 28 6e 9c b6 00 24 74 39 |......I.(n...$t9| af e9 3d 30 c1 77 d0 43 75 0a 4c 73 a6 6c d4 54 |..=0.w.Cu.Ls.l.T| c4 bb 0f c7 50 83 ca 3d 3e d4 93 c0 90 fe a1 25 |....P..=>......%| 4f f3 76 6f 9d 08 27 38 3d b5 74 3c 0c 20 31 30 |O.vo..'8=.t<. 10| b4 4f f3 34 23 40 10 50 00 56 31 fe 45 56 e9 34 |.O.4#@.P.V1.EV.4| 53 2d 16 4e 1b b9 0a 0d 16 a0 f4 12 da 51 a2 3e |S-.N.........Q.>| aa c3 0d 59 3b b8 99 7e 35 33 d2 47 ea f8 08 25 |...Y;..~53.G...%| 95 2a d6 b6 01 bc 57 65 7c bc 12 c2 6f 43 80 65 |.*....We|...oC.e| cb 01 1e 4d c0 74 fa 3a 00 06 3c fb c8 1e 50 2f |...M.t.:..<...P/| c8 dd 27 99 24 75 f8 15 47 6a 17 02 56 14 35 5f |..'.$u..Gj..V.5_| be d9 ad 0d bd 14 01 27 81 86 f9 26 0e 4e 23 e3 |.......'...&.N#.| 08 ea 0e 42 9a 16 1e 1c 5d d6 47 a2 47 d2 e9 ba |...B....].G.G...| 1e 8a e9 f3 1c 20 e1 7d 49 fe d0 32 4f 12 a0 d0 |..... .}I..2O...| 23 83 a2 46 37 cc c8 a1 5a ca cf 6b 04 24 fc c2 |#..F7...Z..k.$..| 0c 47 c3 1d 56 08 53 f6 35 e7 73 51 61 77 19 4c |.G..V.S.5.sQaw.L| fd 19 80 6a 0f 2f f0 e0 c2 be 92 be 6a ff c1 a3 |...j./......j...| 9c 92 90 93 20 61 1e 3f 55 40 73 43 94 dc 78 cc |.... a.?U@sC..x.| 74 4d 01 56 a4 78 2e 4c 08 1d e8 24 e2 0c 8d 51 |tM.V.x.L...$...Q| 1a 83 d2 01 07 84 e2 0c 15 de 81 33 85 ac 48 52 |...........3..HR| 0a 26 3b 4d 90 0b 7a 66 66 08 20 88 c5 9b 9b 58 |.&;M..zff. ....X| 53 f8 c7 e0 fe eb 3a 0b 7e f8 03 2e 2d 6a 24 e8 |S.....:.~...-j$.| 46 5e 53 41 04 60 65 11 87 54 9a 81 e8 46 10 12 |F^SA.`e..T...F..| ba ce 74 bc 59 0b 0f 4d 69 3d 62 1a d2 6a 19 5e |..t.Y..Mi=b..j.^| 70 3a 05 75 e6 dc 2e 50 e3 03 07 10 08 43 ce 51 |p:.u...P.....C.Q| fd 2c 0c a3 dc 4b e1 17 39 75 05 7f 34 b5 52 63 |.,...K..9u..4.Rc| be bf d6 72 3a 86 f2 31 e1 3e 51 b4 07 bf 23 07 |...r:..1.>Q...#.| 4c 8c 2d 6b 4a 81 14 91 5a 0c 03 ca 18 4d 25 20 |L.-kJ...Z....M% | e1 fd c6 8b f7 eb 15 7d 69 d5 35 8b 43 84 07 5f |.......}i.5.C.._| d4 20 cf 31 fc 78 80 0e cb 4e eb b2 eb cc ba fb |. .1.x...N......| 36 0c 74 cb 12 39 41 dd 4f 1b c5 eb 76 ee 09 7b |6.t..9A.O...v..{| 0c b7 75 55 a2 db 24 d8 a3 5f 36 36 50 07 a9 3e |..uU..$.._66P..>| e1 43 52 45 87 e7 32 9e 10 78 5a ef 4c 82 58 0b |.CRE..2..xZ.L.X.| 6a ca 5a 5a 02 aa 3c 84 70 c0 62 03 1a 62 e2 ef |j.ZZ..<.p.b..b..| 43 11 42 86 03 2b c8 14 a8 e7 25 43 a1 1d 14 f0 |C.B..+....%C....| 45 1c 6c 2e 14 85 a0 b7 de 9b a0 0a 14 c7 83 9c |E.l.............| 27 c0 1b 80 1f 84 bc ff 43 22 28 3b 43 2c 99 48 |'.......C"(;C,.H| 08 15 f8 65 0b 61 ea 00 9c 88 88 46 24 42 d8 f0 |...e.a.....F$B..| 3c 4f 0d 84 d5 d3 26 c6 20 96 c2 84 22 ef 7d 0e | |
176 | 2057 | ac 0b 99 07 f4 54 22 84 e5 36 7c 6b b7 d2 a9 d3 |.....T"..6|k....| 80 88 a0 80 83 ac 27 a5 4d 5c da 84 10 b4 90 49 |......'.M\.....I| 37 8c 75 30 ff 4b da 76 8f d0 58 a9 c0 02 3f 88 |7.u0.K.v..X...?.| 1d 58 3b b8 08 2c 1e 06 66 26 9c f4 04 34 01 25 |.X;..,..f&...4.%| 9d 02 da 89 e5 af b0 5c da 16 8a 94 10 74 62 28 |.......\.....tb(| 4e 53 69 0e 88 5a 8b 8c c7 62 03 56 09 e8 30 dc |NSi..Z...b.V..0.| c2 6b 4b 00 8b 33 01 e2 82 4a c5 46 58 3d d9 87 |.kK..3...J.FX=..| 25 a0 48 6c 61 8b 3b a8 c4 c5 e9 02 57 13 8b 41 |%.Hla.;.....W..A| ba 4b 08 56 06 03 d2 0e a0 e2 b0 6e 7d 0d 78 54 |.K.V.......n}.xT| 90 24 ec 02 2f 49 02 18 e8 fd 97 f1 2b b5 66 1d |.$../I......+.f.| 60 4b 30 d1 fa 04 4a 84 4a 22 b2 16 47 48 88 1f |`K0...J.J"..GH..| 84 43 20 7e 1d 64 b0 10 7e 00 b4 0c 74 24 fe 3b |.C ~.d..~...t$.;| 53 20 7c b5 bb 1b d9 6a 3c 48 1a 96 e2 c2 b7 ed |S |....j |
4992 | 2057 | 2b 4d e8 72 ac 8a a7 ed 5a 14 88 d8 82 72 a3 19 |+M.r....Z....r..| 28 24 21 f3 c8 0f 78 40 97 a4 1a cc 28 01 d3 30 |($!...x@....(..0| 80 08 22 fa b5 43 8b b9 8d 45 b6 3c 48 95 cc 1a |.."..C...E. |
module_name | hint | ord | function_name |
---|---|---|---|
KERNEL32.DLL | LoadLibraryA | ||
KERNEL32.DLL | GetProcAddress | ||
KERNEL32.DLL | VirtualProtect | ||
KERNEL32.DLL | VirtualAlloc | ||
KERNEL32.DLL | VirtualFree | ||
KERNEL32.DLL | ExitProcess | ||
ADVAPI32.dll | AddAce | ||
COMCTL32.dll | ImageList_Remove | ||
COMDLG32.dll | GetSaveFileNameW | ||
GDI32.dll | LineTo | ||
IPHLPAPI.DLL | IcmpSendEcho | ||
MPR.dll | WNetUseConnectionW | ||
ole32.dll | CoGetObject | ||
OLEAUT32.dll | 8 | ||
PSAPI.DLL | GetProcessMemoryInfo | ||
SHELL32.dll | DragFinish | ||
USER32.dll | GetDC | ||
USERENV.dll | LoadUserProfileW | ||
UxTheme.dll | IsThemeActive | ||
VERSION.dll | VerQueryValueW | ||
WININET.dll | FtpOpenFileW | ||
WINMM.dll | timeGetTime | ||
WSOCK32.dll | 23 |
StringTable 080904B0
VS_FIXEDFILEINFO
FileVersion | 0.0.0.0 |
ProductVersion | 0.0.0.0 |
StrucVersion | 0x10000 |
FileFlagsMask | 0 |
FileFlags | 0 |
FileOS | 4 |
FileType | 1 |
FileSubtype | 0 |
Please donate some bucks to keep this site up and running: | |
Ko-fi | |
---|---|
Yandex.Money | |
Thank you! |
[!] string size(16792) > stringtable size(1428). truncated to 1426
[!] cannot convert "\xF2\xB8D@\x1C\xBF\x89Ez:TP\x02\x84\f\x06"... to UTF-16
[!] string size(26976) > stringtable size(1674). truncated to 1672
[!] cannot convert "\xA6\xB6\x98LBh\x1F\\A\xFEV\xC4\xA1\x10!L"... to UTF-16
[!] string size(29470) > stringtable size(1168). truncated to 1166
[!] cannot convert "\x16\xA8\xE1E\x1F\xB8\x03X\xAB\x0F\x7FW\x01J\a\xDC"... to UTF-16
[!] string size(44606) > stringtable size(1532). truncated to 1530
[!] cannot convert "\x04(E:\xA4\x00\xADn\xC4\x8B\rF\x9AZw\xEA"... to UTF-16
[!] string size(10258) > stringtable size(1628). truncated to 1626
[!] cannot convert "\n\x14\v\f\x14\r\x14\x0E\x14\x0F\x10#\x17\xDB\xFE\x14"... to UTF-16
[!] string size(5976) > stringtable size(1126). truncated to 1124
[!] cannot convert "\x99\a\xF4T\"\x84\xE56|k\xB7\xD2\xA9\xD3\x80\x88"... to UTF-16
[!] string size(39510) > stringtable size(344). truncated to 342
[!] cannot convert "\xE8r\xAC\x8A\xA7\xEDZ\x14\x88\xD8\x82r\xA3\x19($"... to UTF-16